First published: Mon Nov 29 2021(Updated: )
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wipro Holmes | =20.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-38147.
CVE-2021-38147 has a severity value of 7.5 (high).
CVE-2021-38147 affects Wipro Holmes Orchestrator version 20.4.1.
The impact of CVE-2021-38147 is that remote attackers can download arbitrary files, including reports containing sensitive information, without requiring authentication.
At the moment, there are no known fixes available for CVE-2021-38147. It is recommended to follow the vendor's security advisories and apply patches or updates as soon as they become available.